6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25659
ASPRunner Professional General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

ASPRunner Professional 6.0.766 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long project name. Attackers can paste 180 or more characters into the Project name field during project creation to trigger an application crash.

CVE-2019-25665
River Past Ringtone Converter General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

River Past Ringtone Converter 2.7.6.1601 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to activation fields. Attackers can paste 300 bytes of data into the Email textbox and Activation code textarea via the Help menu's Activate dialog to trigger a denial of service condition.

CVE-2019-25594
ASPRunner.NET General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-807 1 PoC

ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the table name field. Attackers can input a buffer of 10000 characters in the table name parameter during database table creation to trigger an application crash.

CVE-2019-25599
Backup Key Recovery General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-466 1 PoC

Backup Key Recovery 2.2.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 or more characters into the Name field during registration to trigger a crash when submitting the form.

CVE-2019-25625
Blob Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1285 1 PoC

Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of repeated characters and trigger the application to read it, causing the application to crash or become unresponsive.

CVE-2019-25485
R Windows
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the GUI Preferences language menu field that allows local attackers to bypass DEP and ASLR protections. Attackers can inject a crafted payload through the Language for menus preference to trigger a structured exception handler chain pivot and execute arbitrary shellcode with application privileges.

CVE-2019-25653
Navicat for Oracle Database
6.9
MEDIUM
EPSS
0.0%
2019 CWE-620 1 PoC

Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer of 550 repeated characters into the password parameter during Oracle connection configuration to trigger an application crash.

CVE-2019-25484
WinMPG iPod Convert General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

WinMPG iPod Convert 3.0 contains a buffer overflow vulnerability in the Register dialog that allows local attackers to crash the application by supplying an oversized payload. Attackers can paste a large string of characters into the User Name and User Code field to trigger a denial of service condition.

CVE-2019-25660
LanHelper General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

LanHelper 1.74 contains a local buffer overflow vulnerability that allows attackers to crash the application by sending excessively long input strings. Attackers can exploit the Form Send Message feature by pasting 6000 bytes of data into the Message text field to trigger a denial of service condition.

CVE-2019-25632
phpFileManager Web
6.9
MEDIUM
EPSS
0.0%
2019 CWE-306 1 PoC

phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.

CVE-2019-25572
NordVPN Networking
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1260 1 PoC

NordVPN 6.19.6 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the email input field. Attackers can paste a buffer of 100,000 characters into the email field during login to trigger an application crash.

CVE-2019-25617
Ease Audio Converter General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-226 2 PoCs

Ease Audio Converter 5.30 contains a denial of service vulnerability in the Audio Cutter function that allows local attackers to crash the application by processing malformed MP4 files. Attackers can create a crafted MP4 file containing an oversized buffer and load it through the Audio Cutter interface to trigger an application crash.

CVE-2019-25623
Luminance Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-641 1 PoC

Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can create a text file with arbitrary character sequences and trigger the application to process the input, causing the application to become unresponsive or terminate abnormally.

CVE-2019-25595
jetAudio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-469 1 PoC

jetAudio 8.1.7.20702 Basic contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string through the URL input handler. Attackers can trigger the crash by pasting a buffer of 5000 characters into the Open URL dialog, causing the application to terminate abnormally.

CVE-2019-25569
RealTerm: Serial Terminal General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

RealTerm Serial Terminal 2.0.0.70 contains a stack-based buffer overflow vulnerability in the Echo Port field that allows local attackers to crash the application by triggering a structured exception handler (SEH) chain corruption. Attackers can craft a malicious input string with 268 bytes of padding followed by SEH overwrite values and paste it into the Port field to cause denial of service.

CVE-2019-25338
Dokuwiki General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-204 1 PoC

DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.

CVE-2019-25598
HeidiSQL Portable Database
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

HeidiSQL Portable 10.1.0.5464 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer overflow payload into the password input during Microsoft SQL Server login to trigger an application crash.

CVE-2019-25592
PHPRunner Web
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1260 1 PoC

PHPRunner 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the dashboard name field. Attackers can paste a buffer of 10000 characters into the Name field during dashboard creation to trigger an application crash.

CVE-2019-25666
SpotAuditor General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition.

CVE-2019-25583
RarmaRadio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1282 1 PoC

RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash the application by submitting excessively long input. Attackers can paste a buffer of 5000 bytes into the Username field via Settings > Network to trigger an application crash.